Epic Skills Assessment Information Security & HIPAA Compliance 1 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered Protected Health Information (PHI)?
- A patient's name combined with their diagnosis (Correct answer)
- A general description of a medical condition with no patient identifiers
- Aggregate statistics from de-identified patient data
- A physician's personal contact information
Correct answer: A patient's name combined with their diagnosis
PHI is any individually identifiable health information, including a patient's name linked to their medical condition.
Question 2: Which HIPAA rule specifically governs the security of electronic protected health information (ePHI)?
- The Privacy Rule
- The Breach Notification Rule
- The Security Rule (Correct answer)
- The Enforcement Rule
Correct answer: The Security Rule
The HIPAA Security Rule establishes national standards to protect ePHI that is created, received, used, or maintained by covered entities.
Question 3: An Epic user shares their login credentials with a colleague covering their shift. This is a violation of which security principle?
- Data minimization
- Accountability and non-repudiation (Correct answer)
- Role-based access control
- Encryption standards
Correct answer: Accountability and non-repudiation
Sharing credentials undermines accountability and non-repudiation, since actions can no longer be traced to the individual who performed them.
Question 4: A hospital employee accesses the medical record of a celebrity patient out of curiosity, without clinical need. This is best described as a violation of:
- The minimum necessary standard (Correct answer)
- Break-the-glass access protocol
- Business associate agreement requirements
- The HITECH Act's audit controls
Correct answer: The minimum necessary standard
The minimum necessary standard requires that access to PHI be limited to only what is required to accomplish the intended purpose.
Question 5: Which of the following is an example of a physical safeguard required by the HIPAA Security Rule?
- Automatic logoff after a period of inactivity
- Workstation screens positioned to prevent unauthorized viewing (Correct answer)
- Encryption of ePHI during transmission
- Audit logs of access to patient records
Correct answer: Workstation screens positioned to prevent unauthorized viewing
Workstation positioning to prevent unauthorized viewing is a physical safeguard that controls physical access to systems containing ePHI.
Question 6: Under HIPAA's Breach Notification Rule, covered entities must notify affected individuals of a PHI breach within how many days?
- 30 days
- 45 days
- 60 days (Correct answer)
- 90 days
Correct answer: 60 days
The Breach Notification Rule requires covered entities to notify affected individuals no later than 60 calendar days after discovery of a breach.
Question 7: In Epic, 'break-the-glass' access is designed to:
- Allow administrators to reset user passwords in emergency situations
- Permit authorized users to access records outside their normal permissions when clinically necessary (Correct answer)
- Automatically log out users who leave workstations unattended
- Enable bulk data exports for research purposes
Correct answer: Permit authorized users to access records outside their normal permissions when clinically necessary
Break-the-glass allows authorized users to override normal access restrictions in urgent clinical situations, with all such access logged for audit review.
Under HIPAA, which of the following is considered Protected Health Information (PHI)?